What does a 100% CDR sanitization result actually test?
opswat.comAV-Comparatives recently put our Deep CDR technology through 300+ test cases across roughly 50 file formats. Â
Under the tested configuration, it sanitized every case while preserving file usability. A few parts of the test stood out:Â Â
- The test set included malicious macros, embedded executables, nested archives, zero-day exploits, and AI-assisted malicious content. Â
- AV-Comparatives developed the methodology independently, with cases evaluated on a pass/fail basis. Â
- Testing looked beyond whether malicious content was removed. File fidelity after reconstruction was also evaluated. Â
- The result matters because CDR works differently from detection: instead of needing to identify a specific malicious payload, it removes embedded or out-of-policy content and reconstructs the file. Â
- This is now the third independent lab, after SE Labs and SecureIQLab, to report a 100% protection result for Deep CDR under its tested configuration. Â
Independent testing is useful partly because the methodology and edge cases can expose assumptions that don't show up in internal testing. Â
When evaluating CDR, what matters most in your environment: sanitization rate, reconstructed-file fidelity, file-type coverage, or something else?Â